{"id":"https://openalex.org/W7163063774","doi":"https://doi.org/10.4230/lipics.forc.2026.8","title":"Can We Watermark Low-Entropy LLM Outputs?","display_name":"Can We Watermark Low-Entropy LLM Outputs?","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7163063774","doi":"https://doi.org/10.4230/lipics.forc.2026.8"},"language":"en","primary_location":{"id":"pmh:oai:drops-oai.dagstuhl.de:25980","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.8","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.8/LIPIcs.FORC.2026.8.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},"type":"article","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.8/LIPIcs.FORC.2026.8.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5110804370","display_name":"Noam Mazor","orcid":null},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mazor, Noam","raw_affiliation_strings":["New York University, NY, USA"],"raw_orcid":"https://orcid.org/0009-0003-3390-9317","affiliations":[{"raw_affiliation_string":"New York University, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133630100","display_name":"Andrew Morgan","orcid":null},"institutions":[{"id":"https://openalex.org/I205783295","display_name":"Cornell University","ror":"https://ror.org/05bnh6r87","country_code":"US","type":"education","lineage":["https://openalex.org/I205783295"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Morgan, Andrew","raw_affiliation_strings":["Cornell Tech, New York, NY, USA"],"raw_orcid":"https://orcid.org/0009-0007-0812-359X","affiliations":[{"raw_affiliation_string":"Cornell Tech, New York, NY, USA","institution_ids":["https://openalex.org/I205783295"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5135504970","display_name":"Rafael Pass","orcid":null},"institutions":[{"id":"https://openalex.org/I16391192","display_name":"Tel Aviv University","ror":"https://ror.org/04mhzgx49","country_code":"IL","type":"education","lineage":["https://openalex.org/I16391192"]},{"id":"https://openalex.org/I174306211","display_name":"Technion \u2013 Israel Institute of Technology","ror":"https://ror.org/03qryx823","country_code":"IL","type":"education","lineage":["https://openalex.org/I174306211"]},{"id":"https://openalex.org/I205783295","display_name":"Cornell University","ror":"https://ror.org/05bnh6r87","country_code":"US","type":"education","lineage":["https://openalex.org/I205783295"]}],"countries":["IL","US"],"is_corresponding":false,"raw_author_name":"Pass, Rafael","raw_affiliation_strings":["Technion, Haifa, Israel","Cornell Tech, New York, NY, USA","Tel Aviv University, Israel"],"raw_orcid":"https://orcid.org/0000-0001-7440-5690","affiliations":[{"raw_affiliation_string":"Technion, Haifa, Israel","institution_ids":["https://openalex.org/I174306211"]},{"raw_affiliation_string":"Cornell Tech, New York, NY, USA","institution_ids":["https://openalex.org/I205783295"]},{"raw_affiliation_string":"Tel Aviv University, Israel","institution_ids":["https://openalex.org/I16391192"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.89251797,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.576200008392334,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.576200008392334,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.06939999759197235,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.044199999421834946,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.9517999887466431},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.8995000123977661},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.6209999918937683},{"id":"https://openalex.org/keywords/entropy","display_name":"Entropy (arrow of time)","score":0.6039999723434448},{"id":"https://openalex.org/keywords/alphabet","display_name":"Alphabet","score":0.5764999985694885},{"id":"https://openalex.org/keywords/fraction","display_name":"Fraction (chemistry)","score":0.5496000051498413},{"id":"https://openalex.org/keywords/constant","display_name":"Constant (computer programming)","score":0.51419997215271},{"id":"https://openalex.org/keywords/conditional-entropy","display_name":"Conditional entropy","score":0.4253000020980835},{"id":"https://openalex.org/keywords/substring","display_name":"Substring","score":0.40869998931884766}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.9517999887466431},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.8995000123977661},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.6209999918937683},{"id":"https://openalex.org/C106301342","wikidata":"https://www.wikidata.org/wiki/Q4117933","display_name":"Entropy (arrow of time)","level":2,"score":0.6039999723434448},{"id":"https://openalex.org/C112876837","wikidata":"https://www.wikidata.org/wiki/Q837518","display_name":"Alphabet","level":2,"score":0.5764999985694885},{"id":"https://openalex.org/C149629883","wikidata":"https://www.wikidata.org/wiki/Q660926","display_name":"Fraction (chemistry)","level":2,"score":0.5496000051498413},{"id":"https://openalex.org/C2777027219","wikidata":"https://www.wikidata.org/wiki/Q1284190","display_name":"Constant (computer programming)","level":2,"score":0.51419997215271},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.4950000047683716},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4823000133037567},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.4756999909877777},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4481000006198883},{"id":"https://openalex.org/C101721835","wikidata":"https://www.wikidata.org/wiki/Q813908","display_name":"Conditional entropy","level":3,"score":0.4253000020980835},{"id":"https://openalex.org/C182407805","wikidata":"https://www.wikidata.org/wiki/Q2626534","display_name":"Substring","level":3,"score":0.40869998931884766},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.397599995136261},{"id":"https://openalex.org/C171752962","wikidata":"https://www.wikidata.org/wiki/Q255166","display_name":"Kullback\u2013Leibler divergence","level":2,"score":0.3587999939918518},{"id":"https://openalex.org/C108801101","wikidata":"https://www.wikidata.org/wiki/Q15032","display_name":"Steganography","level":3,"score":0.3497999906539917},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.33390000462532043},{"id":"https://openalex.org/C81081738","wikidata":"https://www.wikidata.org/wiki/Q55542","display_name":"Lossless compression","level":3,"score":0.3296999931335449},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.31610000133514404},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.3093999922275543},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3093999922275543},{"id":"https://openalex.org/C160633673","wikidata":"https://www.wikidata.org/wiki/Q355198","display_name":"Pixel","level":2,"score":0.29420000314712524},{"id":"https://openalex.org/C44415725","wikidata":"https://www.wikidata.org/wiki/Q4913893","display_name":"Binary entropy function","level":3,"score":0.29179999232292175},{"id":"https://openalex.org/C78548338","wikidata":"https://www.wikidata.org/wiki/Q2493","display_name":"Data compression","level":2,"score":0.26570001244544983},{"id":"https://openalex.org/C97399411","wikidata":"https://www.wikidata.org/wiki/Q825367","display_name":"Coin flipping","level":2,"score":0.26100000739097595},{"id":"https://openalex.org/C125252325","wikidata":"https://www.wikidata.org/wiki/Q1345213","display_name":"Entropy rate","level":4,"score":0.25769999623298645},{"id":"https://openalex.org/C118615104","wikidata":"https://www.wikidata.org/wiki/Q121416","display_name":"Discrete mathematics","level":1,"score":0.2524000108242035},{"id":"https://openalex.org/C1769480","wikidata":"https://www.wikidata.org/wiki/Q1345239","display_name":"Entropy encoding","level":3,"score":0.25209999084472656}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:drops-oai.dagstuhl.de:25980","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.8","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.8/LIPIcs.FORC.2026.8.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},{"id":"doi:10.4230/lipics.forc.2026.8","is_oa":true,"landing_page_url":"https://doi.org/10.4230/lipics.forc.2026.8","pdf_url":null,"source":{"id":"https://openalex.org/S7407052059","display_name":"Dagstuhl Research Online Publication Server","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":""}],"best_oa_location":{"id":"pmh:oai:drops-oai.dagstuhl.de:25980","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.8","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.8/LIPIcs.FORC.2026.8.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7163063774.pdf","grobid_xml":"https://content.openalex.org/works/W7163063774.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"A":[0,236,253],"recent":[1,84],"and":[2,181,260,301],"exciting":[3],"thread":[4],"of":[5,15,37,111,119,131,137,154,162,179,202,210,272,292],"work":[6,85],"focuses":[7],"on":[8,22,128,223],"developing":[9],"methods":[10],"for":[11],"watermarking":[12,25,237,254],"the":[13,34,38,46,50,57,61,80,129,135,138,155,163,177,192,200,208,213,221,224,265,270,273,281],"output":[14,35,47,51,136,164,271],"large":[16],"language":[17],"models":[18],"(LLMs).":[19],"We":[20],"focus":[21],"provably":[23],"undetectable":[24],"-":[26,148,235,252],"that":[27,30,48,71,104,149,269],"is,":[28,150],"schemes":[29,103],"do":[31],"not":[32],"alter":[33],"distribution":[36],"LLM,":[39],"yet":[40],"enable":[41],"embedding":[42],"a":[43,108,116,151,158,218,290,293],"watermark":[44,62,207],"in":[45,134,157,247],"identifies":[49],"as":[52,246],"having":[53],"been":[54],"generated":[55],"by":[56,68,284],"particular":[58],"LLM.":[59,139],"Furthermore,":[60],"should":[63],"be":[64,189],"hard":[65],"to":[66,100,166,188,280,298],"remove":[67],"an":[69],"adversary":[70],"may":[72],"potentially":[73],"edit,":[74],"insert,":[75],"or":[76,113,227,289],"delete":[77],"tokens":[78,156],"from":[79],"watermarked":[81],"output.":[82],"Indeed,":[83],"(Christ":[86],"et":[87,91,95,183,249,286],"al.":[88,92,96,184,250,287],"[COLT'24],":[89],"Christ":[90,248,285],"[CRYPTO\u201924],":[93],"Golowich":[94,182],"[NeuroIPS\u201924])":[97],"shows":[98],"how":[99],"develop":[101],"such":[102],"are":[105],"robust":[106,239,256,297],"against":[107,115,240,257],"constant":[109,117,145,152],"fraction":[110,118,153],"substitutions,":[112],"even":[114],"arbitrary":[120],"edits.":[121],"These":[122],"works,":[123],"however,":[124],"make":[125],"strong":[126],"assumptions":[127],"amount":[130],"entropy":[132,146,169,215],"present":[133],"Most":[140],"notably,":[141],"they":[142],"all":[143],"require":[144,186],"rate":[147],"sufficiently":[159],"long":[160],"substring":[161],"need":[165],"have":[167],"empirical":[168],"at":[170],"least":[171],"O(log":[172],"|T|),":[173],"where":[174],"T":[175,187],"is":[176,216],"alphabet":[178,225],"tokens,":[180],"additionally":[185],"larger":[190],"than":[191],"security":[193,228],"parameter.":[194,229],"In":[195,230],"this":[196,231],"work,":[197],"we":[198,204,233],"consider":[199],"question":[201],"whether":[203],"can":[205],"also":[206],"outputs":[209],"LLMs":[211],"when":[212],"per-token":[214],"just":[217],"constant,":[219],"discarding":[220],"dependence":[222],"size":[226],"regime,":[232],"construct:":[234],"scheme":[238,255],"random":[241,258,261,277,302],"substitutions":[242,259,300],"(assuming":[243],"subexponential":[244],"LPN,":[245],"[CRYPTO\u201924])":[251,288],"deletions,":[262],"given":[263],"either":[264],"additional":[266],"heuristic":[267],"assumption":[268,282],"LLM":[274],"only":[275],"introduces":[276],"errors":[278],"(analogous":[279],"made":[283],"construction":[291],"pseudorandom":[294],"error-correcting":[295],"code":[296],"adversarial":[299],"deletions.":[303]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-06-02T00:00:00"}
